Data Processing Agreement
Last updated: May 1, 2026
This document is published in French and in English. In case of any discrepancy between the two versions, the French version prevails.
1. Introduction and scope
This Data Processing Agreement (hereinafter the “ETD” or “DPA”) is an addendum to the Meo Terms of Use (the “Terms”) entered into between 9553-6785 Québec Inc., a company incorporated under the laws of Quebec, which operates the Meo document management software (hereinafter “Meo”, “we” or the “Mandatary”), and the entity that accepted the Terms (hereinafter the “Client” or the “Mandator”).
This DPA applies when Meo processes Personal Information on behalf of the Client in the course of providing the Services. Its purpose is to ensure that this processing complies with the Act respecting the protection of personal information in the private sector (chapter P-39.1), as amended by Law 25 (SQ 2021, c. 25), and that it respects the rights of the individuals concerned.
In the event of a conflict between this DPA and the Terms, this DPA prevails with respect to the processing of Personal Information.
2. Definitions
“CAI”
The Commission d'accès à l'information du Québec, the provincial body responsible for the protection of personal information.
“Client Data”
All data, including Personal Information, submitted, stored, sent or received by the Client, its authorized users or its external collaborators in the course of using the Services.
“Confidentiality Incident”
Any unauthorized access to, use of or communication of Personal Information, as well as any loss of Personal Information or any other breach in the protection of such information, within the meaning of sections 3.5 to 3.8 of P-39.1.
“Applicable Law”
The Act respecting the protection of personal information in the private sector (chapter P-39.1), Law 25 (SQ 2021, c. 25), the Civil Code of Québec, and any other law or regulation applicable to the protection of personal information in Quebec and in Canada.
“Personal Information”
Any information which relates to a natural person and allows that person to be identified, directly or indirectly, within the meaning of section 2 of P-39.1.
“Privacy Officer”
The person in charge of the protection of personal information designated in accordance with section 3.1 of P-39.1.
“Services”
The Meo document management software, including the client portal, the document collection features, secure storage, and any related service provided under the Terms.
“Subsequent Vendor”
Any third party authorized by Meo to process Client Data on behalf of the Client in the course of providing the Services.
3. Roles of the parties
For the purposes of this DPA, the parties acknowledge that:
The Client acts as a person carrying on an enterprise who collects and holds Personal Information about its own clients and employees (hereinafter the “Mandator” within the meaning of Quebec civil law).
Meo acts as a mandatary or as a party performing a contract for services within the meaning of section 18.3 of P-39.1, processing Client Data solely on behalf of the Client and in accordance with its instructions.
This DPA constitutes the written mandate required by section 18.3, paragraph 2, subparagraph (1) of P-39.1.
4. Description of the processing
4.1 Object and purpose: Meo processes Client Data only for the following purposes: secure document storage, management of document requests and client portals, encryption, backup, access logging, and any feature inherent to the Services as described in the Terms.
4.2 Categories of individuals concerned: The individuals whose Personal Information may be processed include:
- The Client's clients
- The Client's employees
- The Client's external collaborators
- Any natural person whose information appears in the documents uploaded to Meo
4.3 Types of personal information: The types of information that may be processed include, without limitation:
- Names, addresses, telephone numbers, email addresses
- Identification numbers
- Financial and tax information
- Any other personal information contained in the documents uploaded by the Client
4.4 Duration of the processing: Processing starts on the date the Client's account is activated and ends in accordance with section 12 of this DPA.
5. Meo's obligations (section 18.3 of P-39.1)
In accordance with section 18.3 of P-39.1, Meo undertakes the following obligations:
5.1 Purpose limitation: Meo processes Client Data exclusively in the performance of this contract for services and for the provision of the Services.
Meo expressly undertakes not to use Client Data for the purposes of:
- Advertising, profiling or marketing
- Training artificial intelligence models
- Analysis of aggregated or disaggregated data for commercial purposes
- Any other purpose not expressly provided for in the Terms or in this DPA
5.2 Confidentiality protection measures: In accordance with section 18.3, paragraph 2, subparagraph (2) of P-39.1, Meo implements and maintains the following technical and organizational measures:
Encryption
- In transit: TLS 1.3 for all communications
- At rest: AES-256 for all Client Data
Access control
- Principle of least privilege
- Multi-factor authentication mandatory in production
- No access to document contents except on express request
Hosting and location
- Data stored exclusively in Quebec (AWS ca-central-1, Montréal)
- No document stored outside Canada
Document integrity
- SHA-256 fingerprint on upload
- Complete audit log of every action
5.2.5 Organizational security: All Meo personnel are bound by contractual confidentiality obligations. Meo is in the process of achieving SOC 2 Type 2 compliance. A Cloudflare web application firewall (WAF) is in place to protect against threats.
5.3 Personnel confidentiality: Meo ensures that every person authorized to process Client Data is subject to a contractual confidentiality obligation and has received adequate training on the protection of personal information.
5.4 Privacy by default (section 9.1)
In accordance with section 9.1 of P-39.1, the confidentiality settings of the Services are set by default to the highest level of protection, with no action required from the Client.
6. Notification of confidentiality incidents
In accordance with section 18.3, paragraph 2, subparagraph (2) of P-39.1, Meo undertakes to notify the Client's privacy officer for the protection of personal information without delay of any violation or attempted violation of the obligations relating to the confidentiality of Client Data.
6.1 Content of the notification: The notification will include, to the extent the information is available:
- The nature of the Confidentiality Incident
- The categories and approximate number of individuals concerned
- A description of the Personal Information involved
- An assessment of the risk of injury to the individuals concerned
- The measures taken or contemplated to mitigate the consequences
6.2 Cooperation: Meo will provide reasonable cooperation to the Client so that it can meet its own notification obligations towards the CAI and the individuals concerned (sections 3.5 to 3.8 of P-39.1).
6.3 Register of incidents: Meo maintains a register of confidentiality incidents in accordance with section 3.8 of P-39.1, kept for a minimum period of five (5) years.
7. Right of verification
In accordance with section 18.3, paragraph 2, subparagraph (2) of P-39.1, Meo allows the Client's Privacy Officer to carry out any verification relating to compliance with the confidentiality obligations set out in this DPA.
7.1 Procedure
- The Client may request, once (1) per twelve (12) month period, a verification of Meo's compliance with the obligations of this DPA.
- The request must be made in writing, with reasonable advance notice of at least thirty (30) days.
- The verification may take the form of a written questionnaire, a documentary review, or an audit conducted by an independent third party chosen by mutual agreement.
- Meo will make available to the Client its SOC 2 compliance reports (when available), its penetration test reports, and any other relevant documentation.
7.2 Confidentiality of the results: The results of any verification are treated as confidential information of Meo and may not be disclosed to third parties without Meo's written consent, unless the law requires it.
8. Subsequent Vendors
8.1 General authorization: The Client authorizes Meo to use the Subsequent Vendors listed below for the provision of the Services.
8.2 Meo's obligations towards its vendors: Before entrusting the processing of Client Data to a Subsequent Vendor, Meo makes sure that:
- A written contract imposing at least equivalent protection obligations is in place
- The level of protection offered is equivalent to or higher than the level required by Applicable Law
- Meo remains fully liable to the Client for the acts and omissions of its Subsequent Vendors
8.3 Notice of change: Meo will inform the Client by email at least thirty (30) days before authorizing a new Subsequent Vendor to process Client Data. The Client may object in writing within that period. If a reasonable objection is left unresolved, the Client may terminate the affected Services.
8.4 List of current vendors
| Vendor | Location | Function | Data processed |
|---|---|---|---|
| AWS (ca-central-1) | Montréal, QC | Hosting and storage | Documents, account data, metadata |
| Supabase | Montréal, QC | Database and auth. | Account data, authentication, files |
| Stripe | United States | Payments | Billing data (not stored by Meo) |
| Postmark | United States | Transactional emails | Name, email, notification content |
| Cloudflare | Global (transit) | Security and CDN | Data in transit only (TLS 1.3) |
For the up-to-date list of our vendors, see our privacy policy.
9. Transfers outside Quebec (section 17 of P-39.1)
Some Subsequent Vendors (Stripe, Postmark) may process limited Personal Information in the United States. For those transfers:
- Data processing agreements are in place with each Subsequent Vendor
- The level of protection is equivalent to or higher than the level required by Applicable Law
- Meo provides the Client with the information needed to carry out the privacy impact assessment (PIA) required by section 17 of P-39.1
On request, Meo makes available detailed documentation of its security measures and those of its Subsequent Vendors in order to make it easier for the Client to complete its PIA.
10. Rights of the individuals concerned
Meo will assist the Client, as far as possible and taking into account the nature of the processing, so that it can respond to requests from individuals exercising their rights under Applicable Law:
| Right | How Meo supports it |
|---|---|
| Right of access | One-click export of the client's data from the dashboard |
| Right of rectification | Tools to edit and update data |
| Right to erasure | One-click anonymization, permanent deletion |
| Right to portability | Export in structured formats: CSV, JSON, XML |
| Right to de-indexing | Meo neither publishes nor indexes Client Data |
The Client remains responsible for responding to requests from the individuals concerned within the thirty (30) day period provided for by Applicable Law.
11. Cooperation on PIAs (section 3.3)
Meo cooperates with the Client in carrying out the privacy impact assessments (PIAs) required by section 3.3 of P-39.1, by providing:
- The technical security documentation for the Services
- Information on the location of the processing and on the Subsequent Vendors
- The available compliance and audit reports (SOC 2, penetration tests)
- Any other reasonably necessary information
12. Return and destruction of data
In accordance with section 18.3, paragraph 2, subparagraph (2) of P-39.1, Meo will not retain Client Data after the expiry or termination of the Terms.
12.1 Retrieval period
For a period of thirty (30) days following the end of the contract, the Client can download all of its Client Data from its dashboard.
12.2 Destruction
After the retrieval period:
- Client Data in production will be deleted within sixty (60) days
- Backup copies will be purged within ninety (90) days
- On request, Meo will provide written confirmation of the destruction
12.3 Exceptions
Meo may keep Personal Information beyond the periods above only to the extent that Applicable Law requires it (for example, billing documents for tax purposes).
13. Client obligations
The Client undertakes to:
- Designate a Privacy Officer for the protection of personal information in accordance with section 3.1 of P-39.1 and provide Meo with their contact details
- Make sure that the Personal Information transmitted to Meo was collected in accordance with Applicable Law, including obtaining the necessary consents
- Carry out the privacy impact assessments (PIAs) required by Applicable Law, in particular in the case of a transfer outside Quebec (section 17 of P-39.1)
- Respond to requests from the individuals concerned within the time limits prescribed by Applicable Law
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms, unless Applicable Law provides otherwise.
Meo remains liable for the acts and omissions of its Subsequent Vendors in the processing of Client Data.
15. Term and termination
This DPA takes effect on the date the Client accepts the Terms and stays in force for as long as Meo processes Client Data on behalf of the Client.
The provisions relating to confidentiality, to the destruction of data and to liability survive termination.
16. Amendments
Meo may amend this DPA to reflect legislative, regulatory or operational changes. In the case of a substantial amendment, Meo will inform the Client by email at least thirty (30) days before it takes effect.
If the Client does not accept the amendment, it may terminate the Services before the date on which the amendment takes effect.
17. Governing law and jurisdiction
This DPA is governed by the laws of Quebec and the laws of Canada applicable therein. Any dispute will be submitted to the exclusive jurisdiction of the courts of the judicial district of Québec.
18. Contact
For any question relating to this DPA or to the protection of Client Data:
Version 1.0: May 1, 2026
Next scheduled review: May 1, 2027